This is not a change in behaviour; even with the previous implementation the
secrets DB was opened whenever the encrypted FS was mounted; this patch just
makes this behaviour more explicit, therefore leading to some code
simplifications.